Security Training Catalogue
Interactive 3D exercises across phishing, GDPR compliance, the EU AI Act, OWASP Top 10 for LLM & Agentic AI, OWASP Privacy Risks, and real-world incident case studies. Free to play, no sign-up required.
Security Awareness
70 exercises · Build a security-first culture with interactive exercises covering phishing, social engineering, device security, and more.
Phishing
Spot a phishing email before you click.
- Identify spoofed senders and URLs
- Recognize credential theft attempts
- Report phishing through proper channels
Ransomware
Survive a ransomware attack in real time.
- Respond to a live ransomware scenario
- Follow containment and isolation steps
- Preserve evidence for forensic analysis
Social Engineering
Recognize manipulation before you comply.
- Detect pretexting and authority scams
- Practice verification under pressure
- Understand the human element in breaches
Vishing
Handle a realistic voice phishing call.
- Detect caller ID spoofing tactics
- Practice callback verification steps
- Resist urgency and authority pressure
Whaling With A Deepfake
Spot an AI-generated executive on a video call.
- Detect deepfake video call indicators
- Verify identity during live meetings
- Learn from the $25M Hong Kong case
USB Drop Attack
Think twice before plugging in that USB drive.
- Recognize planted USB devices
- Understand Rubber Ducky payloads
- Follow safe handling procedures
Privacy & Compliance Frameworks
37 exercises · Master GDPR, the EU AI Act, and OWASP privacy risks with hands-on exercises covering data protection, breach response, AI governance, and privacy by design.
Data Breach Response
Triage a breach and meet the 72-hour notification clock.
- Apply Article 33 notification requirements
- Assess breach severity and reporting thresholds
- Draft a supervisory authority notification
Cross-Border Data Transfers
Navigate transfer mechanisms for data leaving the EEA.
- Select the right transfer mechanism (SCCs, BCRs)
- Conduct a Transfer Impact Assessment
- Apply Schrems II safeguard requirements
Legitimate DSAR Processing
Process a data subject access request end to end.
- Verify requester identity under Article 15
- Search and compile data across systems
- Meet the 30-day response deadline
Marketing Consent Management
Build compliant opt-in flows that regulators accept.
- Apply GDPR Article 7 consent standards
- Design proper consent withdrawal mechanisms
PII Document Redaction
Redact personal data from documents before disclosure.
- Strip PII from text and metadata layers
- Avoid recoverable redaction failures
Data Protection Impact Assessment
Run a DPIA for a high-risk data processing activity.
- Identify Article 35 DPIA triggers
- Apply structured risk assessment methodology
- Document DPO consultation outcomes
AI & LLM Security
21 exercises · Prepare for AI-powered threats including prompt injection, deepfake attacks, and LLM manipulation.
Prompt Injection Attack
Stop a hidden prompt from hijacking your AI assistant mid-task.
- Detect hidden instructions embedded in documents processed by AI
- Trace how injected prompts override legitimate AI behavior
- Apply safe document handling before feeding content to AI tools
AI Training Data Poisoning
Watch poisoned documents corrupt your AI's answers in real time.
- Trace how manipulated documents alter AI-generated outputs
- Identify signs of data poisoning in AI responses
- Apply content integrity controls to knowledge base inputs
Sensitive Data Exposure Through AI
See what happens when confidential data enters a consumer AI tool.
- Recognize sensitive data categories that should never enter AI prompts
- Trace how pasted content persists in AI training data and logs
- Apply data classification policies before using AI tools
AI System Prompt Extraction
Extract hidden instructions from a customer-facing AI chatbot.
- Execute prompt extraction techniques against a live AI chatbot
- Identify sensitive information exposed through leaked system prompts
- Apply prompt hardening techniques to prevent system instruction disclosure
AI Agent Goal Hijacking
Stop an autonomous AI agent from being redirected by a poisoned email containing hidden instructions.
- Detect hidden instructions embedded in incoming data that redirect agent objectives
- Trace how a goal-hijacked agent pivots from legitimate tasks to data exfiltration
- Apply input validation strategies that prevent agents from treating data as instructions
Detecting a Rogue AI Agent
Investigate a compromised AI agent that appears functional while silently performing unauthorized actions and evading monitoring.
- Detect covert unauthorized actions performed by an agent that appears to be operating normally
- Trace persistence mechanisms that allow rogue agents to survive restarts and monitoring sweeps
- Apply behavioral analysis and anomaly detection to distinguish rogue agents from legitimate ones
Real-World Incidents
2 exercises · Learn from actual security breaches. Walk through the MGM Resorts attack, BEC fraud cases, and more.
MGM Resorts Breach
Relive the 10-minute helpdesk call that cost $100M.
- Recognize helpdesk vishing techniques
- Understand Scattered Spider social engineering
- Trace the path from phone call to ransomware
OneNote Email Attack
Trace a real BEC scam built on weeks of inbox surveillance.
- Detect lookalike domain invoice fraud
- Spot signs of long-term email monitoring
The Developer Track
Application security split by attack surface. Free, hands-on, no sign-up.
-
Application Security
22 exercisesSQL Injection · Stored XSS · Server-Side Request Forgery
-
API Security
10 exercisesBroken Object Level Authorization · Mass Assignment · Excessive Data Exposure
-
Git & Repository Security
8 exercisesSecrets in Git History · Exposed .git Directory · Malicious Pull Requests
- Soon
Cloud Security
IAM, S3 exposure, Kubernetes
See RansomLeak in Action
Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.